feat(auth) : sync Sudloh profiles and validate sessions

This commit is contained in:
2026-10-06 00:48:29 +07:00 Unverified
parent d6153be50d
commit c856904c12
16 changed files with 520 additions and 32 deletions
+3 -3
View File
@@ -14,13 +14,13 @@ BETTER_AUTH_SECRET=replace-with-at-least-32-random-bytes
# Separate trusted browser origins with commas for local development or proxies.
BETTER_AUTH_TRUSTED_ORIGINS=http://localhost:3000
# Optional Sudloh Account sign-in. Register the exact HTTPS callback before enabling.
# Leave client ID and secret unset until the account service operator assigns them.
# Optional Sudloh Account sign-in. A verified Sudloh administrator registers the
# exact HTTPS callback at https://account.sudloh.com/account → OIDC clients.
SUDLOH_OIDC_ISSUER=https://account.sudloh.com/api/auth
SUDLOH_OIDC_CLIENT_ID=
SUDLOH_OIDC_CLIENT_SECRET=
SUDLOH_OIDC_REDIRECT_URI=
# Set only after migration and conflict review to route all new sign-ins through Sudloh.
# Set after linking existing Guide accounts; this also enables Sudloh session checks.
SUDLOH_OIDC_ONLY=false
# Resend sending key; verify sudloh.com before sending from [email protected].